CVE-2012-5331

asaanCart 0.9 - Path Traversal via Page Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2012-5331. PoCs published by Number 7.

AI-analyzed exploit summary The exploit demonstrates XSS and LFI vulnerabilities in asaancart v-0.9 via the smarty_ajax plugin. It includes proof-of-concept URLs for both XSS and LFI attacks, targeting specific endpoints like calc.php, chat.php, and index.php.

Description

Directory traversal vulnerability in asaanCart 0.9 allows remote attackers to include arbitrary local files via a .. (dot dot) in the page parameter to index.php.

Exploits (1)

exploitdb WRITEUP
by Number 7 · textwebappsphp
https://www.exploit-db.com/exploits/18599

The exploit demonstrates XSS and LFI vulnerabilities in asaancart v-0.9 via the smarty_ajax plugin. It includes proof-of-concept URLs for both XSS and LFI attacks, targeting specific endpoints like calc.php, chat.php, and index.php.

Classification
Writeup 90%
Attack Type
Xss | Info Leak
Complexity
Trivial
Reliability
Reliable
Target: asaancart v-0.9
No auth needed
Prerequisites: Access to the target web application · Browser with JavaScript enabled for XSS
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/52498
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/74065
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/18599

Scores

EPSS 0.0235
EPSS Percentile 81.5%

Details

CWE
CWE-22
Status published
Products (1)
nasir_khan/asaancart 0.9
Published Oct 08, 2012
Tracked Since Feb 18, 2026